Governance framework & guidance
Control versus Action
A Control is a safeguard used to reduce or manage a governance risk or requirement. A Governance Action is work that someone needs to complete. Put simply: a Control describes what must remain true; an Action describes what someone needs to do to make it true.
Keeping these concepts separate prevents a completed task from creating the false impression that an ongoing safeguard no longer needs attention.
Controls should be proportionate
Not every AI Use needs the same safeguards. An internal drafting assistant may require simple human review, while AI influencing employment decisions may need stronger oversight, testing, privacy controls, transparency and contestability arrangements.
Controls should address an identified need rather than be added because they sound like good practice.
Evidence and effectiveness
For important Controls, evidence may be needed to support the conclusion that the safeguard exists and is operating. Evidence can include procedures, test results, supplier assurance, access configurations, training records or review outcomes.
Evidence coverage is not the same as effectiveness. A document can prove a procedure exists without proving people follow it or that it actually reduces the relevant Risk.
A Control should not reduce risk merely because it exists
Where a Control contributes to residual-risk reduction, Swell can require that it is linked to the relevant Risk, recognised as relevant, implemented, owned, supported by current evidence where required, verified and considered effective.
This avoids paper Controls creating artificial confidence.
Reuse existing organisational Controls
AI governance does not require organisations to invent entirely new controls where effective safeguards already exist. Privacy, cybersecurity, procurement, incident management, change management and quality assurance controls can be reused where they genuinely address the AI-specific context.
The important question is whether the existing safeguard adequately addresses the requirement, not whether it was originally labelled an “AI Control”.
Using Swell AI
Controls and approval readiness
Controls affect whether an AI Use is ready for an approval decision. Approvers should be able to see which material safeguards are required, which are complete, which remain outstanding, whether evidence gaps exist, and which residual Risks remain.
Approval conditions can also become accountable Controls or Actions so they do not disappear into approval comments.